Remote code execution in Wazuh server
An unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster)…
An unsafe deserialization vulnerability allows for remote code execution on Wazuh servers. The vulnerability can be triggered by anybody with API access (compromised dashboard or Wazuh servers in the cluster)…
In a Facebook post, the Sault Ste. Marie Tribe of Chippewa Indians writes that their IT systems suffered a ransomware attack on Sunday morning, February 9. “This attack impacted multiple…
On Friday, January 31, Tata Technologies reported a cybersecurity incident to the National Stock Exchange of India. According to the letter, a ransomware incident prompted the multinational company to temporarily…
On Sunday, January 26, New York Blood Center Enterprises (NYBCe) detected suspicious activity on their IT systems; third-party investigators confirmed the incident was ransomware. NYBCe provides blood products to more…
The South African Weather Service (SAWS), South Africa’s government-operated weather service, has been disrupted by a cyberattack. SAWS is a critical service for the country’s transportation and agricultural sectors as…
Sam Curry and Shubham Shah have released a report demonstrating a now-patched vulnerability in Starlink, Subaru's multipurpose onboard services system, that would have allowed an attacker to remotely manipulate any…
Researchers from the University of Florida and North Carolina State University have identified nearly 120 vulnerabilities in the LTE / 5G core infrastructure. The flaws affect seven LTE implementations and…
Microsoft has published a reminder that driver synchronization updates via Windows Server Update Services (WSUS) will be deprecated as of April 18, 2025. Microsoft initially announced the deprecation in June…
On Tuesday, January 21, Oracle released their quarterly Critical Patch Update. The release addresses more than 300 vulnerabilities across Oracle’s product and service lines. Among the vulnerabilities fixed in the…
On Wednesday, January 22, Cisco released updates to address three vulnerabilities: a critical privilege elevation issue in the REST API of Cisco Meeting Management; a high-severity denial-of-service vulnerability in the…